Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:94485 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 22295 invoked from network); 12 Jul 2016 01:39:09 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 12 Jul 2016 01:39:09 -0000 Authentication-Results: pb1.pair.com header.from=yohgaki@ohgaki.net; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=yohgaki@ohgaki.net; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain ohgaki.net designates 180.42.98.130 as permitted sender) X-PHP-List-Original-Sender: yohgaki@ohgaki.net X-Host-Fingerprint: 180.42.98.130 ns1.es-i.jp Received: from [180.42.98.130] ([180.42.98.130:37870] helo=es-i.jp) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id C6/A5-17655-93A44875 for ; Mon, 11 Jul 2016 21:39:08 -0400 Received: (qmail 117555 invoked by uid 89); 12 Jul 2016 01:39:01 -0000 Received: from unknown (HELO mail-qt0-f172.google.com) (yohgaki@ohgaki.net@209.85.216.172) by 0 with ESMTPA; 12 Jul 2016 01:39:01 -0000 Received: by mail-qt0-f172.google.com with SMTP id u25so922635qtb.1 for ; Mon, 11 Jul 2016 18:39:00 -0700 (PDT) X-Gm-Message-State: ALyK8tIWLSI/afcZ0y1MInVd79tIOATO6gdVGlPcsO+JPo6dEaGRLSl9ds25KSMIZdTB1WbnBWTW15eN95mbjQ== X-Received: by 10.200.35.78 with SMTP id b14mr33771430qtb.41.1468287535095; Mon, 11 Jul 2016 18:38:55 -0700 (PDT) MIME-Version: 1.0 Received: by 10.140.17.33 with HTTP; Mon, 11 Jul 2016 18:38:15 -0700 (PDT) In-Reply-To: References: Date: Tue, 12 Jul 2016 10:38:15 +0900 X-Gmail-Original-Message-ID: Message-ID: To: "internals@lists.php.net" Content-Type: text/plain; charset=UTF-8 Subject: Re: [RFC][VOTE] Session ID without hashing From: yohgaki@ohgaki.net (Yasuo Ohgaki) Hi all, On Sat, Jul 2, 2016 at 4:35 PM, Yasuo Ohgaki wrote: > Currently session module uses obsolete MD5 for session ID. With > CSPRNG, hashing is redundant and needless. It adds hash module > dependency and inefficient (There is no reason to use hash for CSPRNG > generated bytes). > > This proposal cleans up session code by removing hash. > > https://wiki.php.net/rfc/session-id-without-hashing > > I set vote requires 2/3 support. > Please describe the reason why when you against this RFC. Reasons are > important for improvements! > > Thank you! Thank you for voting and the RFC has passed 13 vs 5. I'll prepare documents and merge the change in a few days. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net